# Hyperoru > Hyperoru is evidence-backed architecture intelligence for security and engineering teams. Hyperoru reconciles code, cloud, CI/CD, scanner, upload, and scoped MCP evidence into a software architecture model. Every material entity and relationship can carry provenance, observation time, confidence, contradictions, and history. This file is a curated map of Hyperoru's public product, technical, trust, and learning pages. Use product pages for positioning and capability boundaries, documentation for current implementation behaviour, trust pages for data handling, and field notes for evidence-backed design guidance. ## Platform and product - [Hyperoru home](https://hyperoru.com/): High-level explanation of Hyperoru's evidence-backed architecture intelligence platform. - [Architecture intelligence](https://hyperoru.com/product): How repository, cloud, CI/CD, scanner, and human observations become current architectural truth. - [MCP context gateway](https://hyperoru.com/mcp): Interactive explanation of scoped MCP evidence, context reconciliation, planned managed connectors, and agent boundaries. - [Security approach](https://hyperoru.com/security): How findings are connected to reachability, trust boundaries, confidence, and human-controlled remediation. - [Guided audit demo](https://hyperoru.com/demo): A deterministic walkthrough of architecture, findings, agents, costs, reports, and remediation. - [AI providers](https://hyperoru.com/providers): Current production models, role boundaries, retention, costs, and provider evaluation. - [Product roadmap](https://hyperoru.com/roadmap): Current capabilities, next evidence sources, and long-term platform direction. ## Documentation and developer workflows - [Documentation home](https://docs.hyperoru.com/docs): Technical setup, architecture, integration, workflow, and API documentation. - [API v1 documentation](https://docs.hyperoru.com/docs/api): The versioned REST API and authenticated workflow contract. - [MCP evidence gateway guide](https://docs.hyperoru.com/docs/integrations/uploads-mcp): Workspace API keys, structured evidence, validated ZIP ingestion, safety checks, and isolated audit execution. - [Agents, context, and MCP](https://docs.hyperoru.com/docs/architecture/agents-context-and-mcp): Bounded agent work, workspace context, evidence tools, and MCP. - [GitHub integration](https://docs.hyperoru.com/docs/integrations/github): Repository connection and authorization behaviour. ## Learning and research - [Field notes](https://hyperoru.com/blog): Practical guides for security architects, AI architects, platform teams, and security engineers. - [Resource library](https://hyperoru.com/resources): Guides, references, and interactive material organised by review question. - [Benchmark methodology](https://hyperoru.com/benchmarks): Evaluation rules for evidence, citations, isolation, replayability, decisions, and cost. - [Category comparison](https://hyperoru.com/compare): How architecture intelligence works with code, cloud, and repository security platforms. - [Evidence-backed security architecture](https://hyperoru.com/blog/evidence-backed-security-architecture): How to move from diagrams to inspectable architectural truth. - [Security engineering context engines](https://hyperoru.com/blog/security-engineering-context-engine): Why findings need system, identity, exposure, and provenance context. - [AI agent security architecture](https://hyperoru.com/blog/ai-agent-security-architecture): Boundaries, context provenance, tool access, and human approval for multi-agent systems. - [Trust boundaries and blast radius](https://hyperoru.com/blog/trust-boundaries-blast-radius): How architectural evidence supports structural path analysis. - [Benchmarking AI security architecture reviews](https://hyperoru.com/blog/benchmark-ai-security-architecture-review): Reproducible evaluation without grading prose. - [Architecture intelligence vs security scanners](https://hyperoru.com/blog/architecture-intelligence-vs-security-scanners): Different product jobs and a shared evidence model. - [Governed model routing](https://hyperoru.com/blog/governed-model-routing-security-agents): Provider flexibility with fixed evidence and authority boundaries. - [Secure MCP evidence gateways](https://hyperoru.com/blog/mcp-evidence-gateway-security-architecture): Scoped API keys, ZIP ingestion, provenance, and bounded workflow actions. - [Continuous review checklist](https://hyperoru.com/blog/continuous-security-architecture-review-checklist): A practical review rhythm for fast-moving systems. ## Trust, privacy, and legal - [Security and compliance controls](https://hyperoru.com/compliance): Current controls, scanner versions, licences, release gates, and compliance evidence. - [Privacy](https://hyperoru.com/privacy): Account data, confidential workspace evidence, AI processing, telemetry, retention, deletion, and customer controls. - [Data Processing Agreement](https://hyperoru.com/dpa): Standard data processing terms, subprocessors, security commitments, and customer rights. - [Terms of use](https://hyperoru.com/terms): Private-beta account duties, acceptable use, confidential evidence, service limits, and termination. - [Cookie policy](https://hyperoru.com/cookies): Essential cookies, optional analytics, consent storage, and preference controls. ## Company and access - [Company thesis](https://hyperoru.com/company): Why Hyperoru treats architecture as a current, evidence-backed model rather than a static diagram. - [Brand system](https://hyperoru.com/brand): Logo, colour, typography, motion, interface, voice, and asset guidance. - [Request access or book a call](https://hyperoru.com/contact): Private access request and architecture call booking. ## Current product facts and boundaries - Repository code is treated as untrusted input. - Audits do not run repository builds, tests, hooks, package scripts, or uploaded code. - One GitHub App handles authorization, selected-project access, and human-approved pull requests with operation-scoped tokens. - Agent outputs use typed artifacts, evidence identifiers, confidence, and decisions. - Reports and remediation pull requests require human approval. - Remediation pull requests are never merged automatically. - The private-beta MCP gateway accepts scoped evidence and validated artifacts; the broader managed source connector and MCP-aware agent experiences are roadmap items. - Marketing demonstrations use illustrative workspace data and label planned capabilities as coming soon. - The production AI gateway uses provider-pinned models, `store: false`, and metadata-only retention.